Sceawere
Vulnerability Detail
CVE-2026-71078UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Oracle Agile PLM MCAD Connector Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.2
- Creation Date
- 3h ago
- Vendor
- Oracle Corporation
- Product
- Oracle Agile PLM MCAD Connector
- Attack Type
- Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Agile PLM MCAD Connector executes to compromise Oracle Agile PLM MCAD Connector. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Agile PLM MCAD Connector accessible data as well as unauthorized read access to a subset of Oracle Agile PLM MCAD Connector accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Agile PLM MCAD Connector.
- Vector String
- CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L
- Attack Complexity
- HIGH
Narrative and Response
Description
Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The supported version that is affected is 3.6. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Agile PLM MCAD Connector executes to compromise Oracle Agile PLM MCAD Connector. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Agile PLM MCAD Connector accessible data as well as unauthorized read access to a subset of Oracle Agile PLM MCAD Connector accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Agile PLM MCAD Connector. CVSS 3.1 Base Score 4.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.2",
"pubDate": "2026-08-18T21:18:07.950Z",
"pubdate": "2026-08-18T21:18:07.950Z",
"executiveSummary": "This vulnerability affects the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain, specifically the CAX Client component version 3.6. It is categorized as a difficult-to-exploit security flaw that allows a low-privileged attacker with local logon access to the target infrastructure to compromise the application.\nSuccessful exploitation of this vulnerability mandates active human interaction from a user other than the attacker. When successfully executed, the attack grants the adversary unauthorized read, update, insert, and delete access to a subset of data accessible by the Oracle Agile PLM MCAD Connector, alongside the capability to trigger a partial denial of service (partial DoS) affecting application availability.\nThe inherent risks involve compromised data confidentiality, integrity, and availability within the targeted environment. Due to the requirement for local access, high attack complexity, and necessary user interaction, the overall baseline severity is mitigated, reflected by a CVSS 3.1 Base Score of 4.2.",
"technicalDetails": "The vulnerability resides within the CAX Client component of the Oracle Agile PLM MCAD Connector version 3.6. Based on the CVSS 3.1 vector (CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L), the attack vector is local (AV:L), meaning the adversary must already possess execution or interactive logon capabilities on the underlying infrastructure where the Oracle Agile PLM MCAD Connector is deployed.\nThe attack complexity is rated as high (AC:H), indicating that successful exploitation relies on specific, non-default conditions or race conditions, and cannot be reliably executed under arbitrary circumstances. Furthermore, the vulnerability requires low privileges (PR:L), signifying that an unprivileged or low-level authenticated user account on the host system is necessary to initiate the attack sequence.\nA critical prerequisite for successful exploitation is human interaction (UI:R). This implies that the threat actor must trick or wait for another user or administrator on the system to perform a specific action, such as executing a secondary process, interacting with a manipulated interface element, or handling specific application data.\nThe attack flow proceeds as follows: First, the low-privileged attacker authenticates locally to the host infrastructure housing the vulnerable Oracle Agile PLM MCAD Connector. Second, leveraging local access and anticipating or inducing the required human interaction from another user, the attacker manipulates application execution states or accessible data handlers within the CAX Client component. Finally, upon successful triggering, the exploit compromises the integrity of the application operations.\nThe resulting post-exploitation impact spans multiple security triads: confidentiality is breached through unauthorized read access to a subset of accessible data; integrity is compromised via unauthorized update, insert, and delete operations against application data; and availability is impaired, leading to a partial denial of service (partial DoS) condition that degrades the operational capability of the Oracle Agile PLM MCAD Connector."
}